Impact
The Master Blocks WordPress plugin, versions 1.4.1 through 1.4.1.4, contains a REST route that lacks authorization checks. An unauthenticated visitor can use this route to modify the plugin’s white‑label setting, which the plugin then outputs unescaped in the admin area. When an administrator visits a wp‑admin page, the injected script runs with the administrator’s privileges, allowing arbitrary JavaScript execution in that context. The vulnerability directly compromises the confidentiality and integrity of the administrator session.
Affected Systems
The affected product is the Master Blocks plugin for WordPress, specifically versions 1.4.1 through 1.4.1.4. All releases before 1.5.0 are unpatched and vulnerable to this issue.
Risk and Exploitability
With a CVSS score of 8.8, this issue is categorized as severity. The vulnerability can be reached from the public internet because the REST route lacks authentication. The EPSS score of <1% indicates a low probability of exploitation in the current landscape, and the vulnerability is not listed in the CISA KEV catalog. Once an attacker injects a malicious script via the white‑label setting, it is stored and later executed in the browser context of any administrator visiting a wp‑admin page, giving the attacker full control over that session and the ability to tamper with site content or data.
OpenCVE Enrichment